Anonymous
2026-08-28 04:34:01
(4 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฎ๐ณ
evicky2002
2026-08-26 07:31:11
(6 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-08-25 22:01:05
(6 days ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
๐บ๐ธ
kosada.com
2026-08-25 16:01:38
(1 week ago)
Web vulnerability probing: /.git/config
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-25 15:50:39
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
mieg
2026-08-25 14:57:01
(1 week ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-25 14:56:45
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-08-25 14:28:40
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-08-25 14:07:14
(1 week ago)
[DateTime=>2026-08-25T14:07:14Z to 2026-08-25T14:07:19Z (UTC)] , [HoneyPot_Hits=>twice] , [HoneyPots ...
show more
[DateTime=>2026-08-25T14:07:14Z to 2026-08-25T14:07:19Z (UTC)] , [HoneyPot_Hits=>twice] , [HoneyPots=>/.git/config] , [total_Hits=>twice]
show less
Bad Web Bot
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-08-25 13:48:57
(1 week ago)
cloudlinux2 fail2ban: 2026-08-25 15:43:52,414 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 15:43:52,414 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 149.88.20.88 - 2026-08-25 15:43:52cloudlinux2 fail2ban: 2026-08-25 15:45:18,449 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 149.88.20.88 - 2026-08-25 15:45:18cloudlinux2 fail2ban: 2026-08-25 15:45:29,705 fail2ban.filter [1464]: INFO [recidive] Found 149.88.20.88 - 2026-08-25 15:45:29cloudlinux2 fail2ban: 2026-08-25 15:45:28,990 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 149.88.20.88 - 2026-08-25 15:45:28cloudlinux2 fail2ban: 2026-08-25 15:45:29,672 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 149.88.20.88cloudlinux2 fail2ban: 2026-08-25 15:46:02,644 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 158.173.242.219 - 2026-08-25 15:46:02cloudlinux2 fail2ban: 2026-08-25 15:46:02,927 fail2ban.filter [1464]: INFO [recidive] Found 158.173.242.219 - 2026-08-25 15:46:02cloudlinux2 fail2ban: 2026-08-25 15:46
show less
Web App Attack
๐ฉ๐ช
sdos.es
2026-08-25 12:42:42
(1 week ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:34:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:34:39.840680 2026] [security2:error] [pid 987:tid 987] [client 158.173.242.219:54609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-langkawi.com"] [uri "/.git/config"] [unique_id "ao1hr9um9cGS00Ol9G_K0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:16:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:16:50.499307 2026] [security2:error] [pid 13978:tid 13978] [client 158.173.242.219:34321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "join.oxfordgliding.com"] [uri "/.git/config"] [unique_id "ao1dglJ3huw10vP62-EWWQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-25 09:11:28
(1 week ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:48:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.242.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:48:24.672688 2026] [security2:error] [pid 10669:tid 10669] [client 158.173.242.219:43077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gestiofiscal.com"] [uri "/.git/config"] [unique_id "ao1IyLI3bE8UfCEGJYUbuAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack